HIPAA & security

Protected messages deserve a protected channel.

This practice is built for HIPAA-aligned operations: encrypted secure chat under a Business Associate Agreement, careful forms, and clear limits on what ordinary web tools can carry.

Secure chat

Secure chat and calendar live inside the signed-in client portal — not on the public website. After login, the chat launcher opens an encrypted vendor channel when a BAA-backed messaging vendor is connected (TLS in transit; vendor encryption at rest, access controls, and audit logs).

Until the vendor is live, the portal chat panel explains the gate. That is intentional — it prevents PHI from landing in a non-compliant public widget.

What is not a secure clinical channel

  • Ordinary consumer email or mailto forms
  • SMS, iMessage, WhatsApp, Facebook, or Instagram
  • Generic website chat tools without a signed BAA
  • Calendar invites that include diagnoses or clinical narrative

Website safeguards

  • HTTPS and security headers on the static site
  • Chat vendor blocked until baaSigned is configured in the site build
  • Inquiry forms require a non-PHI acknowledgment
  • Crisis pathways point to 911 / 988 (this site is not emergency care)

Honest limit

HIPAA compliance is an organizational program — policies, training, vendor BAAs, and technical controls — not a badge a webpage can award itself. StoneCurrent’s site is engineered so PHI can stay on protected systems; the practice must finish BAAs, publish the Notice of Privacy Practices, and enable the secure vendor before clinical messaging goes live.